Description
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so an operator who had protected their dashboard with `USERNAME` / `PASSWORD` (as the older getting started guide documented) loses authentication on upgrade and the dashboard starts open to anyone who can reach its port. The issue is fixed in 1.0.12. The bare `$USERNAME` / `$PASSWORD` are accepted again as a deprecated fallback so previously protected instances stay protected across the upgrade without operator intervention, with a loud deprecation warning at startup directing operators to rename them to `$ESPHOME_USERNAME` / `$ESPHOME_PASSWORD`. The fallback is gated on `$PASSWORD` being set and is only adopted as a pair, so the OS provided `$USERNAME` is never read on its own and the original collision footgun stays closed. A lone bare `$PASSWORD` with no username still fails loud as a credential mismatch rather than starting unauthenticated. This restores compatibility rather than failing closed on the legacy names, because the priority is that an instance which was protected before the upgrade stays protected without the operator having to act; the deprecation warning plus a future removal handles the migration. Operators should migrate to the `$ESPHOME_*` names. The esphome container delivers the fix in the 2026.6.2 release, which bumps its pinned `esphome-device-builder` version to 1.0.12. Without upgrading, restore authentication immediately by setting the new env vars to the same values, on any affected version. Alternatively, do not expose the dashboard port to untrusted networks, and check the startup logs for the `WITHOUT AUTHENTICATION` banner to confirm whether a given instance is currently open.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated dashboard access
Action: Patch immediately
AI Analysis

Impact

The ESPHome Device Builder Dashboard previously used the environment variables $USERNAME and $PASSWORD for authentication. When the internal names were changed to $ESPHOME_USERNAME and $ESPHOME_PASSWORD, the implementation no longer accepted the old names with no fallback, causing the dashboard to start without any authentication after an upgrade. This flaw allows any user who can reach the dashboard port to gain full access, potentially exposing configuration data, controlling connected devices, and facilitating further network compromise. The vulnerability falls under CWE-306, reflecting an improper handling of authentication credentials.

Affected Systems

All deployments of the ESPHome Device Builder dashboard running a version older than 1.0.12, as well as legacy esphome dashboards that still rely on $USERNAME and $PASSWORD, are vulnerable. The esphome container provides the patch in the 2026.6.2 release by upgrading the pinned device-builder to 1.0.12. Any instance that has not applied this update or that has not migrated the environment variables is at risk.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is classified as critical. The EPSS score is < 1%, indicating a very low current exploitation probability, though the CVSS score indicates a severe impact. The vulnerability is not listed in the CISA KEV catalog. Attackers only need network connectivity to the dashboard port and the presence of an upgraded but misconfigured instance that relied on legacy $USERNAME/$PASSWORD variables. Because the dashboard remains open unless operators rename the environment variables or apply the patch, an unauthenticated attack can easily read or modify device configurations, inject commands, or otherwise control devices.

Generated by OpenCVE AI on September 20, 2026 at 22:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ESPHome Device Builder to version 1.0.12 or newer (or upgrade the esphome container to 2026.6.2).
  • After upgrading, rename any existing $USERNAME and $PASSWORD variables to $ESPHOME_USERNAME and $ESPHOME_PASSWORD and remove the old variables.
  • Restrict access to the dashboard port by configuring firewalls or network segmentation to allow only trusted hosts to connect.

Generated by OpenCVE AI on September 20, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rrxg-g2pf-6hh4 ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Esphome
Esphome device-builder
Vendors & Products Esphome
Esphome device-builder

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so an operator who had protected their dashboard with `USERNAME` / `PASSWORD` (as the older getting started guide documented) loses authentication on upgrade and the dashboard starts open to anyone who can reach its port. The issue is fixed in 1.0.12. The bare `$USERNAME` / `$PASSWORD` are accepted again as a deprecated fallback so previously protected instances stay protected across the upgrade without operator intervention, with a loud deprecation warning at startup directing operators to rename them to `$ESPHOME_USERNAME` / `$ESPHOME_PASSWORD`. The fallback is gated on `$PASSWORD` being set and is only adopted as a pair, so the OS provided `$USERNAME` is never read on its own and the original collision footgun stays closed. A lone bare `$PASSWORD` with no username still fails loud as a credential mismatch rather than starting unauthenticated. This restores compatibility rather than failing closed on the legacy names, because the priority is that an instance which was protected before the upgrade stays protected without the operator having to act; the deprecation warning plus a future removal handles the migration. Operators should migrate to the `$ESPHOME_*` names. The esphome container delivers the fix in the 2026.6.2 release, which bumps its pinned `esphome-device-builder` version to 1.0.12. Without upgrading, restore authentication immediately by setting the new env vars to the same values, on any affected version. Alternatively, do not expose the dashboard port to untrusted networks, and check the startup logs for the `WITHOUT AUTHENTICATION` banner to confirm whether a given instance is currently open.
Title ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Esphome Device-builder
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:01:07.730Z

Reserved: 2026-07-02T19:53:48.829Z

Link: CVE-2026-59178

cve-icon Vulnrichment

Updated: 2026-09-14T19:01:00.677Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:37.617

Modified: 2026-09-30T19:08:21.363

Link: CVE-2026-59178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function